mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-08 17:06:15 -08:00
`cleanup-pr-draft.yml` deletes a PR's rolling `test-pr-<n>` draft on `pull_request: closed`. GitHub does not run that workflow when the head ref is already gone at event time, which is exactly what Dependabot does when it supersedes one of its own PRs (close + branch delete in one operation), so those drafts were never collected: 15 orphaned drafts had accumulated, 13 of them Dependabot's. Add a daily `schedule` (plus `workflow_dispatch`) sweep job to the same workflow. It lists every draft whose `tag_name` matches `^test-pr-[0-9]+$`, asks GitHub for that PR's live state, and deletes the draft only when the PR reports `closed`. It fails closed: a lookup error leaves `state` empty and the draft untouched, and a failed listing fails the job rather than sweeping a short list. `test-<branch>` drafts and every other release are outside the tag shape. The event-driven job stays the fast path, now gated on `github.event_name == 'pull_request'`. Workflow-level permissions drop to `contents: read`; the event job takes `actions: write` (cancelling the closed PR's build) and `contents: write`, the sweep only `contents: write`. Verified with a dry run of the sweep script against the live repository: of the 19 `test-pr-<n>` drafts it would delete the 15 closed-PR ones and keep the 4 open-PR ones (#1638, #1637, #1501, #1215). actionlint 1.7.12 with shellcheck at warning severity passes on all workflows. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>